I am providing the scope of ISMS for an organization who has contract with us. We are going to test the feasibility before implementing ISMS. Does anyone have any idea about such an issue?
We have done some research on security and privacy assessment methodology based on the ISO27000 set of standards as well as the Spanish open standard MAGERIT as part of the PRECYSE FP7 EU project (http://www.precyse.eu). Our approach amongst others integrates the open source ISMS tool Verinice (www.verinice.org).
Thanks all for the answers. Actually, we have the manager involved. But the most matter for us is to do feasibility study on the organization before starting to define the scope, etc. How could we measure the feasibility before launching the project?
We have developed an OCIL conformance testsuite according to the Spanish MAGERIT standard which may be useful for doing the initial survey to identify security requirements etc. We expect to release it as an open source testsuite soon.